Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

One-W01F

#21961of 53,624
10.8Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-11999
5.3
2021-04-07
Relic · Relic · CVE-2020-36315
Name of the Vulnerable Software and Affected Versions: RELIC versions prior to 2020-08-01 Description: The issue allows RSA PKCS#1 v1.5 signature forgery due to inadequate checks of the padding and the first two bytes. This requires a low public exponent, such as 3, which is not the default for generated RSA keys. Recommendations: For versions prior to 2020-08-01, consider updating to a version released after 2020-08-01 to resolve the issue. As a temporary workaround, avoid using low public exponents, such as 3, for RSA keys.
PT-2021-12000
5.5
2021-04-07
Relic · Relic · CVE-2020-36316
Name of the Vulnerable Software and Affected Versions: RELIC versions prior to 2021-04-03 Description: The issue is related to a buffer overflow in PKCS#1 v1.5 signature verification. This occurs because garbage bytes can be present, leading to the overflow. Recommendations: For versions prior to 2021-04-03, update to a version released after 2021-04-03 to resolve the issue.